Network message rule matching method and device, switch chip
By optimizing the rule matching algorithm and hardware design, combining the first-in-first-out queue and message analysis engine, the performance bottlenecks of the existing technology when dealing with high-throughput network traffic are solved, efficient network message processing and flexible rule management are achieved, and the system is enhanced.
Patent Information
- Application Number
- CN202411477425.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-10-22
AI Technical Summary
The prior art encounters performance bottlenecks when handling high-throughput network traffic, resulting in slow processing speed, increased latency and insufficient hardware resource utilization, and complex maintenance and update after expansion of rule sets, affecting the scalability and flexibility of the system.
By optimizing the rule matching algorithm and hardware design, the combination of first-in, first-out queues and message resolution engines is adopted to obtain and match network messages, support flexible addition and maintenance of new rules, and improve system scalability.
It significantly improves the speed of network packet processing, reduces latency, meets the needs of high-speed network environments, supports flexible rule management, and improves the scalability and security of the system.
Smart Images

Figure CN119324825B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of network security technology, and in particular, relates to a rule matching method and device for network messages, and a switch chip. Background Art
[0002] Currently, with the increasing complexity and frequency of network attacks and the continuous evolution of network protocols, it is particularly important to effectively match network messages with rules.
[0003] The application of network message rule matching technology enables network devices to automatically identify and process specific types of messages according to predefined standards. This not only helps to identify malicious traffic and implement access control policies, such as resisting distributed denial of service (DDoS) attacks, preventing intrusion attempts, blocking virus propagation, etc., but also optimizes and accelerates legitimate traffic, thereby improving the overall efficiency and security of the network.
[0004] Traditional network packet rule matching methods usually rely on software implementation, which often encounters performance bottlenecks when processing high-throughput network traffic. Since software solutions cannot fully utilize the parallel processing capabilities of modern hardware, they lead to problems such as slow processing speed, increased latency, and insufficient utilization of hardware resources. In addition, as the rule set expands, the complexity and time-consuming maintenance and updating of the rule set continue to increase, which seriously affects the scalability and flexibility of the system. Summary of the invention
[0005] The purpose of the present application is to provide a network message rule matching method and device, and a switch chip, which are used to solve the performance bottleneck problem encountered in the prior art when processing high-throughput network traffic.
[0006] In a first aspect, the present application provides a rule matching method for network packets, comprising: obtaining data packets received by multiple network ports on a switch, and saving the data packets to a working buffer; the data packets encapsulate network packets according to a specific network protocol; recording the starting pointer of the data packet in the working buffer to obtain a first first-in-first-out queue; recording the starting offset obtained by content parsing of the data packet by a message parsing engine to obtain a second first-in-first-out queue; based on the first first-in-first-out queue and the second first-in-first-out queue, obtaining a to-be-matched data packet from the working buffer; matching the to-be-matched data packet with a pre-constructed rule base to obtain a rule matching result; the pre-constructed rule base includes multiple rule matching vectors, each of which corresponds to a combination of specific fields.
[0007] In an implementation of the first aspect, obtaining data packets received by multiple network ports on a switch and saving the data packets to a working buffer includes:
[0008] Obtaining a programming value for limiting a maximum parsing depth of the message parsing engine;
[0009] Polling each of the network ports to obtain the data packet of the programming value size;
[0010] Checking the validity of the data packet and counting the number of words in the data packet;
[0011] When the data packet is valid and the number of words in the data packet is less than or equal to a preset programming value, the data content, end flag and number of valid bytes of the data packet are saved to the working buffer, and the corresponding start pointer is allocated to the data packet in the working buffer.
[0012] In an implementation of the first aspect, based on the first first-in-first-out queue and the second first-in-first-out queue, acquiring the to-be-matched data packet from the working buffer includes:
[0013] When the first FIFO queue and the second FIFO queue are not empty, checking whether a specific data packet skipping condition is met;
[0014] If yes, read the start pointer of the next data packet from the first FIFO queue; read the start offset of the next data packet from the second FIFO queue; based on the start pointer of the next data packet and the start offset of the next data packet, obtain the next data packet from the working buffer as the data packet to be matched;
[0015] Otherwise, read the start pointer of the current data packet from the first first-in-first-out queue, and read the start offset of the current data packet from the second first-in-first-out queue; add the start pointer of the current data packet to the start offset of the current data packet to obtain a read pointer of the data packet to be matched in the working buffer; based on the read pointer of the data packet to be matched, extract the corresponding data packet from the working buffer as the data packet to be matched.
[0016] In an implementation manner of the first aspect, checking whether a specific data packet skipping condition is met includes:
[0017] Get the setting status of each network port on the switch;
[0018] If the network port is set to be enabled, determining that the data packet received from the network port does not satisfy the data packet skipping condition;
[0019] If the network port is set to be disabled, it is determined that the data packet received from the network port meets the data packet skipping condition.
[0020] In an implementation manner of the first aspect, checking whether a specific data packet skipping condition is met includes:
[0021] Obtaining a skip bit identifier set by the message parsing engine and an enable state of a designated port on the message parsing engine; the skip bit identifier includes 0 and 1, where 0 indicates not skipping a data packet and 1 indicates skipping a data packet; the enable state of a designated port on the message parsing engine includes 0 and 1, where 0 indicates enabling the designated port and 1 indicates disabling the designated port;
[0022] Performing an OR operation on the skip bit identifier and the enable state of the designated port to obtain an operation result;
[0023] If the operation result is 0, it is determined that the data packet skipping condition is not met;
[0024] If the operation result is 1, it is determined that the data packet skipping condition is met.
[0025] In an implementation manner of the first aspect, checking whether a specific data packet skipping condition is met includes:
[0026] Determine whether any of the following conditions are true:
[0027] The head of the second FIFO queue declares the skip bit identifier, and the skip bit identifier is set to 1;
[0028] The starting offset of the data packet read from the second FIFO queue is greater than the difference between the length of the specific field and the preset number of bytes;
[0029] The starting offset of the data packet read from the second FIFO queue is assigned a hexadecimal number 0xFF;
[0030] If yes, it is determined that the packet skipping condition is met;
[0031] Otherwise, it is determined that the packet skipping condition is not satisfied.
[0032] In an implementation of the first aspect, matching the to-be-matched data packet with a pre-built rule base to obtain a rule matching result includes:
[0033] Left-aligning the to-be-matched data packet to obtain an aligned data packet;
[0034] Scanning session layer data of the aligned data packets;
[0035] Checking whether there is a field in the session layer data that is consistent with any one of the rule matching vectors in the pre-built rule base;
[0036] If yes, it is determined that the to-be-matched data packet successfully matches the pre-built rule base;
[0037] Otherwise, it is determined that the to-be-matched data packet fails to match the pre-built rule base.
[0038] In an implementation of the first aspect, the method further includes:
[0039] Obtaining the skip bit identifier and the data packet positioning identifier generated by the message parsing engine, and saving them as a third first-in-first-out queue;
[0040] Aligning the skip bit identifier and the data packet address location identifier in the third FIFO queue with the rule matching vector in the rule base to obtain an aligned third FIFO queue;
[0041] The aligned third FIFO queue and the rule matching result are processed based on the multiplexing principle to obtain a final rule matching vector, a final rule matching validity identifier and a final data packet location identifier.
[0042] In a second aspect, the present application provides a rule matching device for network packets, comprising: a data packet cache module, used to obtain data packets received by multiple network ports on a switch, and save the data packets to a working buffer; the data packets encapsulate network packets according to a specific network protocol; a first data recording module, used to record the starting pointer of the data packet in the working buffer to obtain a first first-in-first-out queue; a second data recording module, used to record the starting offset obtained by the message parsing engine performing content parsing on the data packet to obtain a second first-in-first-out queue; a to-be-matched data packet acquisition module, used to obtain the to-be-matched data packet from the working buffer based on the first first-in-first-out queue and the second first-in-first-out queue; a rule matching module, used to match the to-be-matched data packet with a pre-constructed rule base to obtain a rule matching result; the pre-constructed rule base includes multiple rule matching vectors, each of which corresponds to a combination of specific fields.
[0043] In a third aspect, the present application provides a switch chip, comprising: multiple network ports, each of which is used to receive data packets, and the data packets encapsulate network messages according to a specific network protocol; a message parsing engine, used to perform content parsing on the data packets to obtain the starting offset of the data packets; and a rule matching device for network messages as described above.
[0044] As described above, the network message rule matching method and device, and switch chip described in the present application have the following beneficial effects:
[0045] (1) By optimizing the rule matching algorithm and hardware design, the processing speed of network messages is significantly improved, the delay is reduced, and the requirements of high-speed network environment are met;
[0046] (2) It supports the flexible addition and maintenance of new rules, improving the scalability of the system and enabling network operators to quickly deploy and update rules based on the ever-changing network environment and security requirements;
[0047] (3) It can effectively prevent malicious attacks and tampering, protect the security and stability of the network environment, and improve the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 Shown is a schematic diagram of the structure of a switch chip described in this application in one embodiment.
[0049] Figure 2 Shown is a flow chart of an embodiment of the rule matching method for network messages described in the present application.
[0050] Figure 3 Shown is a schematic diagram of the structure of the working buffer described in this application in one embodiment.
[0051] Figure 4 FIG. 1 is a schematic diagram of checking whether a specific packet skipping condition is satisfied in one embodiment of the present application.
[0052] Figure 5 FIG. 1 is a schematic diagram of another embodiment of checking whether a specific packet skipping condition is satisfied as described in the present application.
[0053] Figure 6 Shown is a schematic diagram of the structure of a rule matching device for network messages described in the present application in one embodiment.
[0054] Figure 7 Shown is a structural diagram of another embodiment of the rule matching device for network messages described in the present application.
[0055] Figure 8 Shown is a schematic diagram of the structure of the regular expression engine described in this application in one embodiment. DETAILED DESCRIPTION
[0056] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict.
[0057] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application, and thus the drawings only show components related to the present application rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed at will, and the component layout may also be more complicated.
[0058] In addition, in this application, descriptions such as "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in this field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0059] The following embodiments of the present application provide a network message rule matching method and device, and a switch chip, wherein the network message rule matching method can be applied to Figure 1 The switch chip shown.
[0060] like Figure 1 As shown, the switch chip includes multiple network ports, a message parsing engine (FlexibleParsing Engine, FPE) and a rule matching device (Content Matching Module, CMM) for the network message.
[0061] In one embodiment of the present application, each of the network ports is used to receive a data packet, and the data packet encapsulates a network message according to a specific network protocol.
[0062] It should be noted that the technical solution of the present application is not only applicable to the currently widely used network protocols, such as Transmission Control Protocol / Internet Protocol (TCP / IP) and User Datagram Protocol (UDP), but also has the potential to adapt to new network protocols that may appear in the future.
[0063] In one embodiment of the present application, the network port is further used to queue the data packets in the order of arrival to form an ingress port queue (Ingress Port FIFO, IPF).
[0064] Specifically, the inbound port queue is defined as ipfIntf, which can be expressed as:
[0065] ipfIntf={ipfSop, ipfEop, ipfVld, ipfByteCnt, ipfData, ipfPortNum}
[0066] Among them, ipfSop represents the start mark of the original data packet, ipfEop represents the end mark of the original data packet, ipfVld represents the validity of the original data packet, ipfByteCnt represents the byte count of the original data packet, ipfData represents the data content of the original data packet, and ipfPortNum represents the port number corresponding to the original data packet.
[0067] The number of network ports on the switch chip determines the number of inbound port queues. For example, a switch chip may have 5, 10, or 20 network ports. For each network port, a first-in, first-out (FIFO) queue mechanism is used to achieve efficient data packet management and transmission. Therefore, if a switch chip has 10 network ports, 10 inbound port queues (IPFs) will be formed accordingly.
[0068] In this implementation, the FIFO queue mechanism is used to help maintain the order of data packets and prevent the disorder and loss of data packets, especially when the network traffic is large, and the flow of data packets can be effectively managed.
[0069] In one embodiment of the present application, the message parsing engine is used to perform content parsing on the data packet to obtain a starting offset of the data packet.
[0070] The present application adopts a flexible message parsing engine, which adopts a flexible architecture based on a finite state machine (FSM) and can identify and parse multiple protocol fields through a state transition mechanism.
[0071] Specifically, the output of the message parsing engine is fpeIntf, which can be expressed as:
[0072] fpeIntf={fpeVld, fpel5StartOffset, fpePortNum, fpePkt, fpeSlotId}
[0073] Among them, fpeVld indicates the validity of the parsed data packet, fpel5StartOffset indicates the starting offset of the Ethernet protocol type field; fpePortNum indicates the port number corresponding to the parsed data packet; fpePkt indicates the content of the parsed data packet; fpeSlotId indicates the slot number to which the data packet belongs.
[0074] In one embodiment of the present application, the message parsing engine includes a skip bit setting module and a port status setting module.
[0075] Specifically, the skip bit setting module is used to set a skip bit identifier (fpeSkipPkt). The skip bit identifier includes 0 and 1, wherein 0 indicates not skipping a data packet, and 1 indicates skipping a data packet.
[0076] The port status setting module is used to set the enable status (~cmmPerPortEn[fpePortIndex]) of the designated port on the message parsing engine. The enable status of the designated port on the message parsing engine includes 0 and 1, where 0 indicates enabling the designated port and 1 indicates disabling the designated port.
[0077] In the embodiment of the present application, the starting offset of the data packet is used to indicate the starting position of the actual valid content in the data packet, such as the starting offset of the Ethernet protocol type field. Since the data packet usually contains header information and actual valid data, the starting offset can provide a reference point for the CMM, so that it can skip the header information and directly analyze and process the actual valid data part. This mechanism allows the CMM to efficiently parse the data packet and focus on the analysis of the data content, thereby improving the efficiency and accuracy of data processing.
[0078] The rule matching method of the network message in the embodiment of the present application will be described in detail below in conjunction with the drawings in the embodiment of the present application.
[0079] See also Figure 2 , showing a flow chart of an embodiment of the rule matching method for network messages described in the present application.
[0080] like Figure 2 As shown, the rule matching method for network messages provided in the present application includes the following steps S100 to S500.
[0081] In step S100, data packets received by multiple network ports on the switch are obtained and stored in a working buffer (Cmm working buffer). The data packets are encapsulated into network messages according to a specific network protocol.
[0082] In one embodiment of the present application, obtaining data packets received by multiple network ports on a switch and saving the data packets to a working buffer includes the following steps S101 to S104.
[0083] In step S101, a programming value (CmmInspection Depth) for limiting a maximum parsing depth of the message parsing engine is obtained.
[0084] Specifically, the programming value is stored in a specific register (CmmInspectionDepth register). The register can be designed as an integrated component of the CMM to implement the configuration of the analysis depth.
[0085] In actual application scenarios, the CmmInspectionDepth register allows flexible adjustment of the maximum parsing depth, supporting configuration as 32-bit or 64-bit. This flexibility enables CMM to adapt to the parsing needs of packets of different sizes and complexities while ensuring the efficiency and accuracy of the parsing process. By properly configuring the maximum parsing depth, CMM can avoid unnecessary computing overhead while ensuring parsing quality, thereby improving overall parsing performance.
[0086] In step S102, the data packet of the programmed value size is obtained from each of the network ports through polling.
[0087] In one embodiment of the present application, the maximum parsing depth configured by the CmmInspectionDepth register is 64 bits, and the workflow of the polling mechanism is as follows: when the data packet of a certain network port completes the parsing of 64 bytes, the system will obtain the parsed 64-byte data packet from the port, and then automatically switch to the next network port to continue to obtain the next 64-byte data packet.
[0088] In step S103, the validity of the data packet is checked, and word count of the data packet is performed.
[0089] In one embodiment of the present application, checking the validity of the data packet includes obtaining the value of fpeVld, and determining the validity of the data packet according to the value of fpeVld.
[0090] In one embodiment of the present application, a word counter is used to count the number of words in the statistical data packet.
[0091] Specifically, using a word counter to count the number of words in a data packet includes: each time a start mark of a data packet is detected, the word counter will count once, until an end mark of the data packet is encountered or the number of data words reaches a preset programming value, and the word counter will stop counting.
[0092] In step S104, when the data packet is valid and the number of words in the data packet is less than or equal to a preset programming value, the data content, end flag and number of valid bytes of the data packet are saved to the working buffer, and the corresponding start pointer is allocated to the data packet in the working buffer.
[0093] See also Figure 3, which is a schematic diagram of the structure of the working buffer in one embodiment of the present application. Figure 3 As shown, the working buffer is provided with a counter (Counter), a write logic control unit (WriteControlLogic), a data storage area and a data packet start pointer queue (CmmPktStartPtrFifo).
[0094] Specifically, the input signal of the Counter includes a start flag of a data packet and an end flag of a data packet, which are used to count the number of words in the data packet. The WriteControlLogic is used to control whether data is written to the data storage area based on a preset rule, and the preset rule is that the data packet is valid and the number of words in the data packet is less than or equal to a preset programming value. The data storage area is used to store 512 bits of channelized data, an end flag of a data packet, and the number of valid bytes associated with each 64 bytes. The CmmPktStartPtrFifo is used to locate and point to a specific address in the data storage area.
[0095] In step S200, the start pointer of the data packet in the working buffer is recorded to obtain a first first-in-first-out queue.
[0096] In one embodiment of the present application, the first FIFO queue is a data structure that complies with the FIFO principle and can be expressed as cmmPktStFIfo.
[0097] The cmmPktStFIfo corresponds to the data packet start pointer queue (CmmPktStartPtrFifo) in the working buffer.
[0098] In step S300, the starting offset obtained by the message parsing engine performing content parsing on the data packet is recorded to obtain a second first-in-first-out queue.
[0099] In one embodiment of the present application, the second first-in-first-out queue is a data structure that complies with the first-in-first-out principle and can be expressed as cmml5Stfifo.
[0100] In step S400, based on the first FIFO queue and the second FIFO queue, a to-be-matched data packet is obtained from the working buffer.
[0101] In an embodiment of the present application, based on the first FIFO queue and the second FIFO queue, obtaining the to-be-matched data packet from the working buffer includes the following steps S401 to S403.
[0102] In step S401, when the first FIFO queue and the second FIFO queue are not empty, it is checked whether a specific data packet skipping condition is met.
[0103] See also Figure 4 , which is a schematic diagram of checking whether a specific data packet skipping condition is met in one embodiment of the present application. Figure 4 As shown, checking whether a specific data packet skipping condition is met includes: obtaining the setting status of each network port on the switch; if the network port is set to enabled, it is determined that the data packet received from the network port does not meet the data packet skipping condition; if the network port is set to disabled, it is determined that the data packet received from the network port meets the data packet skipping condition.
[0104] Specifically, the CMM.portEn variable is used to represent the setting status of each network port on the switch. The value of this variable corresponds to the enabled status of the port: a value of 1 indicates that the port is set to enabled (enable), and the system will match and process the data packets of this port; a value of 0 indicates that the port is set to disabled (disable), and the system will skip the data packets of this port.
[0105] See also Figure 5 , which is a schematic diagram of another embodiment of checking whether a specific packet skipping condition is met as described in the present application. Figure 5 As shown, checking whether a specific data packet skipping condition is met includes: obtaining a skip bit identifier (fpeSkipPkt) set by the message parsing engine and an enable state (~cmmPerPortEn[fpePortIndex]) of a designated port on the message parsing engine; the skip bit identifier includes 0 and 1, wherein 0 indicates not skipping a data packet and 1 indicates skipping a data packet; the enable state of the designated port on the message parsing engine includes 0 and 1, wherein 0 indicates enabling the designated port and 1 indicates disabling the designated port; performing an OR operation on the skip bit identifier and the enable state of the designated port to obtain an operation result; if the operation result is 0, it is determined that the data packet skipping condition is not met; if the operation result is 1, it is determined that the data packet skipping condition is met.
[0106] Specifically, if the starting offset is not found within the 512B limit, or the FPE is programmed to skip packets, the FPE sets fpeSkipPkt.
[0107] Whenever FPE sends the fpeVld signal, l5StFifoDataIn={fpel5StartOffset, (fpeScipPkt|~cmmPerPortEn[fpePortIndex]), fpeSlotId} will be pushed into the second first-in-first-out queue.
[0108] In this embodiment, in order to check whether a specific data packet skipping condition is met, it is necessary to perform an OR operation on fpeSkipPk and ˜cmmPerPortEn[fpePortIndex] to generate a final skipping condition.
[0109] In yet another embodiment of the present application, checking whether a specific data packet skipping condition is met includes: determining whether any of the following conditions is true:
[0110] (1) The head of the second FIFO queue declares the skip bit identifier, and the skip bit identifier is set to 1;
[0111] (2) the starting offset of the data packet read from the second FIFO queue is greater than the difference between the length of the specific field and the preset number of bytes;
[0112] (3) The starting offset of the data packet read from the second FIFO queue is assigned a hexadecimal number 0xFF;
[0113] If so, it is determined that the data packet skipping condition is met; otherwise, it is determined that the data packet skipping condition is not met.
[0114] For example, the above conditions (1) to (3) can be described by the following pseudo code:
[0115] skipPktbit coming Cmml5StFifo is set to 1;
[0116] l5StartOffset length of the segment-4B;
[0117] 15StartOffset=0xFF.
[0118] In step S402, if a specific data packet skipping condition is met, the start pointer of the next data packet is read from the first first-in-first-out queue; the starting offset of the next data packet is read from the second first-in-first-out queue; based on the start pointer of the next data packet and the starting offset of the next data packet, the next data packet is obtained from the working buffer as the data packet to be matched.
[0119] In step S403, if the specific data packet skipping condition is not met, the start pointer of the current data packet is read from the first first-in-first-out queue, and the starting offset of the current data packet is read from the second first-in-first-out queue; the start pointer of the current data packet is added to the starting offset of the current data packet to obtain a read pointer of the data packet to be matched in the working buffer; based on the read pointer of the data packet to be matched, the corresponding data packet is extracted from the working buffer as the data packet to be matched.
[0120] In step S500, the data packet to be matched is matched with a pre-built rule base to obtain a rule matching result.
[0121] In one embodiment of the present application, the pre-built rule base includes a plurality of rule matching vectors, each of which corresponds to a combination of specific fields.
[0122] For example, the pre-built rule base is configured to contain 128 rule matching vectors, each of which can be a field of two bytes, a field of four bytes or N bytes, and supports custom concatenation of fields.
[0123] It should be noted that the acquisition of the rule matching vector usually needs to be customized according to the specific application scenario and security policy. These vectors can also be a series of strings, regular expressions or patterns based on specific protocols, which are used to identify and match specific data packets in network traffic.
[0124] In one embodiment of the present application, the data packet to be matched is matched with a pre-built rule base to obtain a rule matching result including: left-aligning the data packet to be matched to obtain an aligned data packet; scanning the session layer (l5 part) data of the aligned data packet; checking whether there is a field in the session layer data that is consistent with any one of the rule matching vectors in the pre-built rule base; if so, it is determined that the data packet to be matched has successfully matched the pre-built rule base; otherwise, it is determined that the data packet to be matched has failed to match the pre-built rule base.
[0125] In computer networks, the transmission of data follows a complex set of protocols that are organized into different layers, each with its own specific functions and data formats. The session layer is the fifth layer of the OSI model, which is responsible for establishing, managing, and terminating sessions between applications. At this level, data is organized into session layer data, which is the L5 part of the network protocol.
[0126] Furthermore, if a field in the session layer data is found to be consistent with at least one rule matching vector in the rule base, then the packet to be matched can be deemed to have successfully matched the pre-built rule base. This may mean that the packet complies with a specific security policy, or further analysis is required to determine whether there is a security threat.
[0127] If all fields in the session layer data do not match any rule matching vector in the rule base, then it is determined that the packet to be matched fails to match the pre-built rule base. This may mean that the packet does not comply with any known security policy or does not contain any known threat characteristics.
[0128] In one embodiment of the present application, the rule matching method for network messages provided by the present application also includes the following steps S700 to S900.
[0129] In step S700, the skip bit identifier (skipPkt) and the data packet location identifier (slotId) generated by the message parsing engine are obtained and saved as a third first-in-first-out queue.
[0130] Specifically, the skip bit identifier and the data packet locator identifier are parameters directly passed from the FPE, wherein the data packet locator identifier is a slot identifier used to identify a specific slot or port on a network device, and the skip bit identifier is used to indicate whether processing of the data packet should be skipped.
[0131] In step S800, the skip bit identifier and the data packet address location identifier in the third FIFO queue are aligned with the rule matching vector in the rule base to obtain an aligned third FIFO queue.
[0132] In the embodiment of the present application, the purpose of the alignment process is to ensure the consistency of the skip bit identifier and the data packet address location identifier with the rule matching vector in the rule base in structure and position. Because the aligned identifier and the rule matching vector can be compared in a standardized manner, the accuracy and efficiency of the matching process can be improved by alignment. This consistency is the key to achieving accurate matching and fast retrieval, which allows the system to quickly identify data packets that meet specific rules, thereby taking corresponding processing measures.
[0133] In step S900, the aligned third FIFO queue and the rule matching result are processed based on the multiplexing principle to obtain a final rule matching vector, a final rule matching validity identifier and a final data packet location identifier.
[0134] The multiplexing principle is a technology that allows multiple signals or data streams to be transmitted simultaneously on a shared communication medium. It enables different signals to effectively reuse the same transmission medium through reasonable resource allocation and scheduling, thereby improving transmission efficiency.
[0135] In the embodiment of the present application, the application of the multiplexing principle is reflected in the management and scheduling of multiple data streams. Specifically, by matching the data packets in the aligned third FIFO queue with the rule matching vector in the rule base, the system can effectively identify and process data packets that meet specific conditions. This process involves monitoring and processing multiple data streams, which is similar to the management of multiple signal streams by multiplexing technology in the communication field.
[0136] It should be noted that the protection scope of the rule matching method for network messages described in the embodiment of the present application is not limited to the execution order of the steps listed in this embodiment. All solutions implemented by adding, reducing or replacing steps in the prior art based on the principles of the present application are included in the protection scope of the present application.
[0137] See also Figure 6 , showing a structural diagram of a rule matching device for network messages described in the present application in one embodiment.
[0138] like Figure 6 As shown, the rule matching device for network messages provided in the present application includes a data packet cache module, a first data recording module, a second data recording module, a to-be-matched data packet acquisition module and a rule matching module.
[0139] See also Figure 7 , showing a structural diagram of another embodiment of the rule matching device for network messages described in the present application.
[0140] In one embodiment of the present application, the data packet buffer module is represented as cmmPktBuffer, which is used to obtain data packets received by multiple network ports on the switch and save the data packets to a working buffer. The data packets encapsulate network messages according to a specific network protocol.
[0141] In one embodiment of the present application, the first data recording module is represented by cmmPktStFIfo, which is used to record the start pointer of the data packet in the working buffer to obtain a first first-in-first-out queue.
[0142] The input data of cmmPktBuffer and cmmPktStFIfo include ipfIntf, which is defined as: ipfIntf = {ipfSop, ipfEop, ipfVld, ipfByteCnt, ipfData, ipfPortNum}, where ipfSop represents the start mark of the original data packet, ipfEop represents the end mark of the original data packet, ipfVld represents the validity of the original data packet, ipfByteCnt represents the byte count of the original data packet, ipfData represents the data content of the original data packet, and ipfPortNum represents the port number corresponding to the original data packet.
[0143] In one embodiment of the present application, the second data recording module is represented by cmml5StFifo, which is used to record the starting offset obtained by the message parsing engine performing content parsing on the data packet to obtain a second first-in-first-out queue.
[0144] The input data of cmml5StFifo includes fpeIntf, which is defined as: fpeIntf = {fpeVld, fpel5StartOffset, fpePortNum, fpePkt, fpeSlotId}, where fpeVld indicates the validity of the parsed data packet, fpel5StartOffset indicates the starting offset of the Ethernet protocol type field; fpePortNum indicates the port number corresponding to the parsed data packet; fpePkt contains the content of the parsed data packet; and fpeSlotId identifies the slot number to which the data packet belongs.
[0145] In one embodiment of the present application, the to-be-matched data packet acquisition module is represented as cmmPktRdIntf, and is used to acquire the to-be-matched data packet from the working buffer based on the first FIFO queue and the second FIFO queue.
[0146] cmmPktRdIntf implements a state machine that is responsible for controlling the read interface of cmmPktBuffer, cmml5StFifo, and cmmPktStFIfo to ensure that the data packets can be processed and forwarded correctly.
[0147] The input data of cmmPktBuffer is represented as pktBuflntf, and the output data is represented as pktRdintf. The definitions of pktBuflntf and pktRdintf are as follows:
[0148] pktBuflntf={pktBufData, pktBufEop, pktBufVldBytes}; pktRdintf={pktRdStart, pktRdEnd, pktRdVid, pktRdData, pktRdVldBytes, pktRdShiftAmt}.
[0149] This counter-based state machine can gracefully handle lost SOP and lost EOP conditions.
[0150] Specifically, if there is a lack of SOP (SOPa...EOPa...EOPb), since the counter is saturated by the EOP and is not initialized until a new SOP is seen, all packet data from EOPa to EOPb will not be written to the packet buffer.
[0151] If EOP is missing, since IPF introduces an error in EOPa (SOPa…EOPa(error)…SOPb…EOPb), this will be handled as any other regular packet with L1 errors.
[0152] In one embodiment of the present application, the rule matching module is used to match the to-be-matched data packet with a pre-built rule base to obtain a rule matching result. The pre-built rule base includes a plurality of rule matching vectors, each of which corresponds to a combination of specific fields.
[0153] Specifically, the rule matching module includes a data packet alignment module and a regular expression engine.
[0154] The data packet alignment module is represented by cmmDataAligner, which is used to left-align the data packet to be matched to obtain an aligned data packet. The cmmDataAligner implements a barrel shifter to cyclically shift the data bits so that the starting bit of the data packet is aligned with the predetermined boundary, thereby achieving left alignment. The design of this shifter allows efficient bit-level operations on data packets during the alignment process, which not only improves the speed of data packet processing, but also reduces data processing errors caused by alignment errors. In addition, cmmDataAligner is also highly flexible and configurable, and can dynamically adjust the number and direction of shifts according to the size and alignment requirements of the data packet. This flexibility enables cmmDataAligner to adapt to a variety of different network protocols and data formats, thereby maintaining efficient and stable performance in a variety of network environments.
[0155] The output data of cmmDataAligner is expressed as regExIntf, and the definition of regExIntf is as follows: regExIntf = {pktStart, pktEnd, pktVld, pktData, pktVldBytes).
[0156] In one embodiment of the present application, the regular expression engine is represented as cmmRegexEngine, which is used to scan the session layer data of the aligned data packet; check whether there is a field in the session layer data that is consistent with any one of the rule matching vectors in the pre-built rule base; if so, it is determined that the data packet to be matched successfully matches the pre-built rule base; otherwise, it is determined that the data packet to be matched fails to match the pre-built rule base.
[0157] A feedback mechanism is introduced in the design of cmmRegexEngine. This mechanism allows cmmRegexEngine to send a "ready" status signal to cmmPktBuffer when data processing is ready. This design ensures the synchronization and coordination of the data processing process, improving the efficiency and responsiveness of the overall system. Through this mechanism, CMMRegexEngine can notify CMMPktBuffer at the appropriate time, so that it can prepare for data transmission in a timely manner, thereby achieving an efficient data processing process.
[0158] cmmRegexEngine is also used to pass ruleHitVld and ruleHitVector to the downstream module, where ruleHitVld is used to indicate whether the rule matching vector is successfully matched. If the value of ruleHitVld is true, it indicates a successful match; if the value of ruleHitVld is false, it indicates a failed match. ruleHitVector is used to indicate the rule matching vector that is actually matched.
[0159] See also Figure 8 , which is a schematic diagram of the structure of the regular expression engine described in this application in one embodiment. Figure 8 As shown, cmmRegexEngine includes cmmRegexEngineStage0, pipeDelay and wordCnt.
[0160] cmmRegexEngineStage0 implements 32 parallel TCAMs that are fed by 4 consecutive bytes provided by pktData. TCAM0 is searched with bytes [0:3], TCAM1 is searched with bytes [1:4], and TCAM31 is searched with bytes [31:34]. (pktData[255:0] = bytes [0:31]). Since TCAM31 requires 3 additional bytes in the second bus word, the engine accumulates 2 bus words before starting the search operation. The matching lines from the 32 tcams will be routed to the corresponding tokens of each rule. For example, if the rule0 token is programmed in rows 0, 1, and 2 of the tcam, then mll0[31:0], mll1[31:0], and mll2[31:0] will be routed to the rule0 module.
[0161] pipeDelay delays the pktStartIntf signal (like pktStart, pktEnd, and pktVld) by the processing delay of cmmRegexEngineStage0 so that the match lines are aligned with the delayed pktIntf signal.
[0162] wordCnt implements a counter that increments with each pktVld signal and is reset on the pktEnd condition. This is mainly used to compare whether the matching offset is within the absolute start and end offset range of the rule.
[0163] In one embodiment of the present application, the rule matching device for network messages provided by the present application further includes a data temporary storage module and a matching result output module.
[0164] The data temporary storage module is represented by cmmStagingFifo, which is used to obtain the skip bit identifier and the data packet location identifier generated by the message parsing engine, and save them as a third first-in-first-out queue; align the skip bit identifier and the data packet address location identifier in the third first-in-first-out queue with the rule matching vector in the rule base to obtain the aligned third first-in-first-out queue.
[0165] The matching result output module is represented as cmmOutputStage, which is used to process the aligned third FIFO queue and the rule matching result based on the multiplexing principle to obtain a final rule matching vector, a final rule matching validity identifier and a final data packet location identifier.
[0166] Specifically, the cmmOutputStage receives the outputs of the cmmRegExEngine and the cmmStagingFifo, and passes the cmmRuleHitVector and cmmRuleHitVld signals downstream.
[0167] The cmmOutputStage implements a simple multiplexer that drives the result with 0 under the skip condition. The following pseudocode describes the behavior of the cmmOutputStage:
[0168] cmmRuleHitvector = (~stFifoEmpty & stFifoskip)? 128'h0 : ruleHitVector;
[0169] cmmRuleHitvld = (~stFifoEmpty & stFifoskip) 丨 ruleHitvld;
[0170] cmmSlotId = stFifoslotId.
[0171] In addition, the cmmOutputStage also controls the read interface of the cmmStagingFifo by asserting stFifoPop. The following pseudocode describes the behavior of the cmmOutputStage:
[0172] stFifoPop = (~stFifoEmpty & stFifoskip) 丨 ruleHitVld.
[0173] In an embodiment of the present application, the rule matching device for network packets provided by the present application further includes a backpressure control module. The backpressure control module is denoted as cmmstall and is used to trigger a backpressure operation on the upstream module when the cmmPktBuffer or cmml5Stfifo is full and not read in time and reaches a preset water level threshold.
[0174] Specifically, when the data volume of the cmmPktBuffer or cmml5Stfifo reaches a critical point, cmmstall will send a signal to the upstream module to instruct it to suspend further writing of data.
[0175] It should be noted that the packet cache module, the first data recording module, the second data recording module, the module for obtaining packets to be matched, and the rule matching module described in the embodiments of the present application correspond one by one to the steps in the above-mentioned rule matching method for network packets, so they will not be elaborated here.
[0176] The rule matching device for network messages provided in the embodiment of the present application can implement the rule matching method for network messages described in the present application, but the implementation device for the rule matching method for network messages described in the present application includes but is not limited to the structure of the rule matching device for network messages listed in the present embodiment. All structural deformations and replacements of the prior art made according to the principles of the present application are included in the protection scope of the present application.
[0177] In the several embodiments provided in the present application, it should be understood that the disclosed system, device or method can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of modules / units is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules or units, which can be electrical, mechanical or other forms.
[0178] The modules / units described as separate components may or may not be physically separated, and the components displayed as modules / units may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules / units may be selected according to actual needs to achieve the purpose of the embodiments of the present application. For example, the functional modules / units in the various embodiments of the present application may be integrated into one processing module, or each module / unit may exist physically separately, or two or more modules / units may be integrated into one module / unit.
[0179] Those of ordinary skill in the art should further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0180] The descriptions of the processes or structures corresponding to the above-mentioned figures have different emphases. For parts that are not described in detail in a certain process or structure, please refer to the relevant descriptions of other processes or structures.
[0181] The above embodiments are merely illustrative of the principles and effects of the present application and are not intended to limit the present application. Anyone familiar with the technology may modify or change the above embodiments without violating the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by a person of ordinary skill in the art without departing from the spirit and technical ideas disclosed in the present application shall still be covered by the claims of the present application.
Claims
1. A rule matching device for network messages, characterized in that: include: The data packet cache module is used to obtain data packets received by multiple network ports on the switch and save the data packets to a working buffer; the data packets are encapsulated into network messages according to a specific network protocol; A first data recording module, used for recording the starting pointer of the data packet in the working buffer to obtain a first first-in-first-out queue; A second data recording module is used to record the starting offset obtained by the message parsing engine performing content parsing on the data packet to obtain a second first-in-first-out queue; the starting offset of the data packet is used to indicate the starting position of the actual valid content in the data packet; A to-be-matched data packet acquisition module, configured to acquire the to-be-matched data packet from the working buffer based on the first FIFO queue and the second FIFO queue; A rule matching module is used to match the to-be-matched data packet with a pre-built rule base to obtain a rule matching result; the pre-built rule base includes a plurality of rule matching vectors, each of which corresponds to a combination of specific fields; It also includes a data temporary storage module and a matching result output module: The data temporary storage module is used to obtain the skip bit identifier and the data packet locating identifier generated by the message parsing engine, and save them as a third first-in-first-out queue; align the skip bit identifier and the data packet locating identifier in the third first-in-first-out queue with the rule matching vector in the rule base to obtain the aligned third first-in-first-out queue; the data packet locating identifier is a slot identifier, which is used to identify a specific slot or port on a network device, and the skip bit identifier is used to indicate whether the processing of the data packet should be skipped; The matching result output module is used to process the aligned third FIFO queue and the rule matching result based on the multiplexing principle to obtain a final rule matching vector, a final rule matching validity identifier and a final data packet location identifier; The rule matching module includes a data packet alignment module and a regular expression engine; The data packet alignment module is used to left-align the to-be-matched data packet, and implements a barrel shifter to cyclically shift data bits so that the start bit of the data packet is aligned with a predetermined boundary; the number of bits and direction of the shift are dynamically adjusted according to the size of the data packet and the alignment requirements; The regular expression engine introduces a feedback mechanism, which allows the regular expression engine to send a status signal to the data packet buffer module when data processing is ready, so as to notify the data packet buffer module at an appropriate time so that the data packet buffer module can prepare for data transmission in a timely manner.
2. A rule matching method for network messages implementing the device of claim 1, characterized in that: include: Acquire data packets received by multiple network ports on the switch, and save the data packets to a working buffer; the data packets are encapsulated into network messages according to a specific network protocol; Recording the starting pointer of the data packet in the working buffer to obtain a first first-in-first-out queue; Recording the starting offset obtained by parsing the data packet by the message parsing engine to obtain a second first-in-first-out queue; the starting offset of the data packet is used to indicate the starting position of the actual valid content in the data packet; Based on the first FIFO queue and the second FIFO queue, obtaining a to-be-matched data packet from the working buffer; The data packet to be matched is matched with a pre-built rule base to obtain a rule matching result; the pre-built rule base includes a plurality of rule matching vectors, each of which corresponds to a combination of specific fields.
3. The method according to claim 2, characterized in that Acquiring data packets received by multiple network ports on a switch and saving the data packets to a working buffer includes: Obtaining a programming value for limiting a maximum parsing depth of the message parsing engine; Polling each of the network ports to obtain the data packet of the programming value size; Checking the validity of the data packet and counting the number of words in the data packet; When the data packet is valid and the number of words in the data packet is less than or equal to a preset programming value, the data content, end flag and number of valid bytes of the data packet are saved to the working buffer, and the corresponding start pointer is allocated to the data packet in the working buffer.
4. The method according to claim 2, characterized in that: Based on the first FIFO queue and the second FIFO queue, acquiring the to-be-matched data packet from the working buffer comprises: When the first FIFO queue and the second FIFO queue are not empty, checking whether a specific data packet skipping condition is met; If yes, read the start pointer of the next data packet from the first FIFO queue; read the start offset of the next data packet from the second FIFO queue; based on the start pointer of the next data packet and the start offset of the next data packet, obtain the next data packet from the working buffer as the data packet to be matched; Otherwise, the start pointer of the current data packet is read from the first first-in-first-out queue, and the start offset of the current data packet is read from the second first-in-first-out queue; the start pointer of the current data packet is added to the start offset of the current data packet to obtain a read pointer of the data packet to be matched in the working buffer; based on the read pointer of the data packet to be matched, a corresponding data packet is extracted from the working buffer as the data packet to be matched.
5. The method according to claim 4, characterized in that Checks to see if specific packet skipping conditions are met include: Get the setting status of each network port on the switch; If the network port is set to be enabled, determining that the data packet received from the network port does not satisfy the data packet skipping condition; If the network port is set to be disabled, it is determined that the data packet received from the network port meets the data packet skipping condition.
6. The method according to claim 4, characterized in that Checks to see if specific packet skipping conditions are met include: Obtaining a skip bit identifier set by the message parsing engine and an enable state of a designated port on the message parsing engine; the skip bit identifier includes 0 and 1, where 0 indicates not skipping a data packet and 1 indicates skipping a data packet; the enable state of a designated port on the message parsing engine includes 0 and 1, where 0 indicates enabling the designated port and 1 indicates disabling the designated port; Performing an OR operation on the skip bit identifier and the enable state of the designated port to obtain an operation result; If the operation result is 0, it is determined that the data packet skipping condition is not met; If the operation result is 1, it is determined that the data packet skipping condition is met.
7. The method according to claim 4, characterized in that Checks to see if specific packet skipping conditions are met include: Determine whether any of the following conditions are true: The head of the second FIFO queue declares the skip bit identifier, and the skip bit identifier is set to 1; The starting offset of the data packet read from the second FIFO queue is greater than the difference between the length of the specific field and the preset number of bytes; The starting offset of the data packet read from the second FIFO queue is assigned a hexadecimal number 0xFF; If yes, it is determined that the packet skipping condition is met; Otherwise, it is determined that the packet skipping condition is not satisfied.
8. The method according to claim 2, characterized in that: The data packet to be matched is matched with a pre-built rule base, and the rule matching results obtained include: Left-aligning the to-be-matched data packet to obtain an aligned data packet; Scanning session layer data of the aligned data packets; Checking whether there is a field in the session layer data that is consistent with any one of the rule matching vectors in the pre-built rule base; If yes, it is determined that the to-be-matched data packet successfully matches the pre-built rule base; Otherwise, it is determined that the to-be-matched data packet fails to match the pre-built rule base.
9. A switch chip, characterized in that: include: A plurality of network ports, each of which is used to receive a data packet, wherein the data packet encapsulates a network message according to a specific network protocol; A message parsing engine, used to parse the content of the data packet to obtain a starting offset of the data packet; the starting offset of the data packet is used to indicate the starting position of the actual valid content in the data packet; The rule matching device for network messages as claimed in claim 1.
Citation Information
Patent Citations
1394 transaction layer data package storage management method and circuit
CN108614792A
Database auditing method, system and equipment under big data stream load
CN110222503A